IT security policy
DTU’s IT security rules for students
The following rules apply to all DTU students, including continuing education students and students at DTU Adgangskursus.
Purpose of the guidelines for the use of IT by DTU students
DTU has established these Guidelines for the Use of IT by DTU Students to define the framework for maintaining good cyber and information security at DTU.
The Guidelines for the Use of IT by DTU Students are intended to ensure that:
- DTU’s systems are only used by DTU students for study-related purposes
- The use and copying of software and data is carried out in a lawful manner
- Unauthorised persons do not gain unauthorised access to DTU’s systems and data
- Data is protected against accidental sharing, deletion or modification
- DTU students’ use of DTU’s systems is carried out in a manner that minimises operational disruptions and avoids unnecessary resource consumption.
Who is covered by the guidelines?
These guidelines apply to you as a student at DTU when you use DTU’s systems, including DTU’s network, regardless of whether you are on DTU premises or accessing DTU’s systems remotely. The guidelines also apply to you if you are a recipient of DTU data made available to you in connection with your study activities.
As a user of DTU’s systems, you are required to keep yourself continuously informed about the applicable rules. There will often be supplementary and more detailed instructions for specific systems or types of information and data you use. These general guidelines may not be deviated from in specific instructions.
Authentication and passwords
Your IT identity, including your username and password, is strictly personal and may only be used by you, i.e. the specific person to whom it has been issued. You must not share information relating to your IT identity, especially your password, with others, or store/keep such information in a way that allows others to access or use it.
DTU does not permit the use of the same password across systems and imposes requirements on password length, complexity, and change frequency. You must also not enter your username and password anywhere other than DTU’s official systems.
If you suspect that passwords, access cards, or other means of access have been compromised, you must immediately attempt to prevent misuse, for example, by changing your password or having access disabled. DTU’s IT Department must always be contacted as soon as possible via the DTU Service Portal.
Copying and protection of data and software
DTU has paid licences for the systems made available to all DTU students. The software must not be used in a manner that violates the licence terms. Licence terms vary between different software packages. The specific rules can be obtained by contacting support for the relevant system/function. They will, where possible, be stated on the website from which the software is downloaded.
If a licence is made available to you, it is for personal use only. Software covered by such a licence must not be copied or installed on equipment other than your personal equipment. Consequently, you must not copy software installed in the computer rooms, student laboratories, etc., for which DTU has an institutional licence. This also applies even if it is technically possible to copy the software without circumventing DTU’s security measures. Software may only be copied if this is specifically stated to be permitted or after obtaining approval from support for the relevant system/function.
DTU data, including research data, or data regarded as the private property of others or as personal data, must not be accessed, copied or otherwise used, including in AI tools, without prior permission or an agreement with the data owner or data controller and, in the case of personal data, unless the processing is carried out in accordance with data protection legislation and DTU’s guidelines. Without a prior agreement with the data owner, it is not permitted to attempt to gain access to such data, even if access can technically be obtained without circumventing DTU’s security measures.
Permitted and prohibited purposes for the use of DTU data or systems
All of DTU’s IT resources, including PCs, servers, licences, printers, disk space, network traffic, external services, etc., may only be used for study-related purposes.
You must not use DTU’s data and systems in a manner that may damage DTU’s reputation. Nor may you publish material on DTU’s systems that may be defamatory or generally offensive.
Most of DTU’s systems may be used lawfully only for research and teaching, which means that other forms of use would constitute a violation of the software licence.
Your use of DTU’s systems must comply with applicable legislation, including copyright law.
As a student, you automatically hold the copyright to software that you develop yourself. When you use compilers, code or material from others in your software, these may be subject to terms and conditions, and you must be aware that this may affect how your software can subsequently be used. If you participate in one of DTU’s research projects, you will often be asked to assign your copyright to the software so that DTU can comply with its agreements with the other participants in the project.
DTU’s networks and servers may only be used to share copyright-protected material when you have obtained permission to do so, either from the rights holder or through a licence, so that the material is not shared in a manner that infringes copyright.
In the context of copyright law, sharing also includes uploading material to AI chatbots, such as Microsoft CoPilot (including when using DTU Login).
If projects involve personal data, it must be processed in accordance with applicable data protection legislation and DTU’s guidelines. Personal data may only be collected and processed for legitimate purposes and only to the extent necessary. The information must be stored and shared securely and must not be used in systems or services that DTU has not approved for the purpose. Personal data must not be entered into AI tools or other external services unless this has been approved in accordance with the university’s guidelines.
Use of DTU’s systems
You must not unnecessarily burden DTU’s systems, for example, through higher-than-expected data storage consumption, use of computing resources or network traffic, without a prior agreement with the provider of the relevant system or function.
You are allocated a data storage quota for personal drives, which must not be exceeded. You cannot transfer an unused quota to other users. DTU backs up user files on certain systems. Still, in principle, you are solely responsible for ensuring that the necessary backup of your data is carried out.
Use of IT equipment
You are not permitted to disconnect or disable any installed security software (antivirus software, etc.) on DTU equipment and systems that you use.
DTU’s IT equipment is the property of DTU and must always be returned to DTU when you no longer need to use it.
Your own equipment must maintain a high level of cybersecurity to be used at DTU, for example, with regard to software updates. Your equipment may be subject to DTU’s security checks, and security requirements may be imposed on your equipment before access to specific systems or data can be granted.
DTU’s use of your data registered in DTU’s systems
As part of the normal operation of DTU’s IT systems, you should be aware that a range of information is collected that can identify you, your behaviour and your activities in DTU’s systems. DTU collects this information to document the accuracy of information in the systems and to identify functional or security vulnerabilities in the IT systems. DTU will not use the information for purposes that are incompatible with those described above. Information will only be disclosed to relevant authorities upon request or in connection with an investigation, in accordance with Danish law. Information collected by DTU will only be used and disclosed in anonymised (statistical) form, unless it concerns investigations of misuse.
DTU reserves the right to examine the content of data and software in user areas, such as personal drives, in connection with operational disruptions and in cases of suspected illegal activity or breaches of the rules.
Reporting information security incidents
You must immediately notify DTU’s IT Department (the Service Portal) if you have reason to believe that information or systems have been compromised and may be accessed by unauthorised persons. Likewise, if you discover that you have access to systems or information that you are not authorised to access, or that are not necessary for study-related activities, you must immediately notify your teachers or DTU’s IT Department. DTU encourages everyone to report observations relevant to cyber and information security at DTU, such as receiving suspicious emails.
Where can you get help?
Questions concerning the use of IT or IT-related problems can be directed to DTU’s IT Department via the Service Portal. It is also possible to receive assistance in person at DTU Library on Lyngby Campus.
Procedure in the event of a breach of these guidelines
If a breach of these guidelines or the rules governing the handling of personal data is suspected, it must be reported to the Office for Study Programmes and Student Affairs via AUS-Sekretariat@dtu.dk.
Violations may result in sanctions (see Study Rules/Disciplinary measures against students on student.dtu.dk).
Following consultation with you and, where relevant, the involvement of other relevant parties, the Office for Study Programmes and Student Affairs will decide the case in accordance with DTU’s disciplinary rules. You may appeal the decision to the Danish Agency for Higher Education and Science. The deadline for submitting an appeal is two weeks from the date on which the decision was communicated to you.
Rules in my study programme
Go to 'My Programme Specification' to see which study rules apply to your study programme.